Windows
Analysis Report
http://4.lkx91.michaelhuegel.com/news?q=IP%20provider%20is%20blacklisted!%20MICROSOFT-CORP-MSN-AS-BLOCK
Overview
General Information
Detection
Score: | 52 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w11x64_office
- chrome.exe (PID: 4484 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 290DF23002E9B52249B5549F0C668A86) - chrome.exe (PID: 1208 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --string-a nnotations =is-enterp rise-manag ed=no --fi eld-trial- handle=181 2,i,567696 8392746827 338,178001 7575008823 4751,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction -- variations -seed-vers ion=202412 08-180523. 718000 --m ojo-platfo rm-channel -handle=22 36 /prefet ch:11 MD5: 290DF23002E9B52249B5549F0C668A86)
- chrome.exe (PID: 7332 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://4.lkx9 1.michaelh uegel.com/ news?q=IP% 20provider %20is%20bl acklisted! %20MICROSO FT-CORP-MS N-AS-BLOCK " MD5: 290DF23002E9B52249B5549F0C668A86)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | SlashNext: |
Phishing |
---|
Source: | Joe Sandbox AI: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | File deleted: | Jump to behavior |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Browser Extensions | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 4 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 File Deletion | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 5 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
100% | SlashNext | Fraudulent Website type: Phishing & Social Engineering |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
4.lkx91.michaelhuegel.com | 185.246.85.141 | true | false | high | |
www.google.com | 142.250.184.228 | true | false | high | |
feeds.foxnews.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown | ||
false | high | ||
false | unknown | ||
false |
| unknown | |
false | unknown | ||
false | high | ||
false |
| unknown | |
false | unknown | ||
false | high | ||
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.184.228 | www.google.com | United States | 15169 | GOOGLEUS | false | |
185.246.85.141 | 4.lkx91.michaelhuegel.com | France | 21409 | IKOULAFR | false |
IP |
---|
192.168.2.24 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1582855 |
Start date and time: | 2024-12-31 17:12:36 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 22s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://4.lkx91.michaelhuegel.com/news?q=IP%20provider%20is%20blacklisted!%20MICROSOFT-CORP-MSN-AS-BLOCK |
Analysis system description: | Windows 11 23H2 with Office Professional Plus 2021, Chrome 131, Firefox 133, Adobe Reader DC 24, Java 8 Update 431, 7zip 24.09 |
Run name: | Potential for more IOCs and behavior |
Number of analysed new started processes analysed: | 22 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal52.win@16/14@8/3 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, BackgroundTransferHost.exe, SIHClient.exe, appidcertstorecheck.exe, conhost.exe, backgroundTaskHost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.184.227, 142.250.184.238, 64.233.167.84, 142.250.185.142, 142.250.185.238, 142.250.186.142, 151.101.2.132, 151.101.66.132, 151.101.130.132, 151.101.194.132, 142.250.181.238, 142.250.185.106, 142.250.185.170, 142.250.184.234, 142.250.185.234, 142.250.185.74, 216.58.206.74, 142.250.186.138, 172.217.16.202, 142.250.185.138, 216.58.212.170, 142.250.186.74, 142.250.186.106, 142.250.186.42, 216.58.212.138, 172.217.18.10, 142.250.185.202, 142.250.74.202, 216.58.206.42, 142.250.184.202, 142.250.184.206, 199.232.214.172, 142.250.186.67, 142.250.185.110, 172.217.16.206, 23.44.203.179, 2.23.209.135, 184.28.90.27, 4.245.163.56, 20.103.156.88, 40.126.32.140
- Excluded domains from analysis (whitelisted): www.bing.com, client.wns.windows.com, fs.microsoft.com, accounts.google.com, j.sni.global.fastly.net, content-autofill.googleapis.com, slscr.update.microsoft.com, fd.api.iris.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, www.googleapis.com, x1.c.lencr.org, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, login.live.com, res.public.onecdn.static.microsoft, update.googleapis.com, clients.l.google.com, c.pki.goog
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenFile calls found.
- Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: http://4.lkx91.michaelhuegel.com/news?q=IP%20provider%20is%20blacklisted!%20MICROSOFT-CORP-MSN-AS-BLOCK
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3195 |
Entropy (8bit): | 4.5774179129707075 |
Encrypted: | false |
SSDEEP: | 48:vu+C1AFRZpvtph6F6BgxVbaCdQciJ2ZBgof6PM5FGxs7vtj:vuT1Yd6ygx4cA2 |
MD5: | 0ED0D9CFCE1D0BBEC965DFF0BF6FF8AB |
SHA1: | F800035B2B5AA2C890A187733CC74BE14DB9A2E5 |
SHA-256: | 1589479C8620C06190C102AB49A0A09E400D1937782983705DD1B4FBC723A83A |
SHA-512: | 7F159E57E3FF086C70EEB6892088FE06B1EFB67C9EF304517AA48977F1D6F1B498DFCF1D4290DD11259656E7C5F014C24F83BE8EF1CAABB85E29A3F533DD2246 |
Malicious: | false |
Reputation: | low |
URL: | http://4.lkx91.michaelhuegel.com/news?q=IP%20provider%20is%20blacklisted!%20MICROSOFT-CORP-MSN-AS-BLOCK |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3195 |
Entropy (8bit): | 4.5774179129707075 |
Encrypted: | false |
SSDEEP: | 48:vu+C1AFRZpvtph6F6BgxVbaCdQciJ2ZBgof6PM5FGxs7vtj:vuT1Yd6ygx4cA2 |
MD5: | 0ED0D9CFCE1D0BBEC965DFF0BF6FF8AB |
SHA1: | F800035B2B5AA2C890A187733CC74BE14DB9A2E5 |
SHA-256: | 1589479C8620C06190C102AB49A0A09E400D1937782983705DD1B4FBC723A83A |
SHA-512: | 7F159E57E3FF086C70EEB6892088FE06B1EFB67C9EF304517AA48977F1D6F1B498DFCF1D4290DD11259656E7C5F014C24F83BE8EF1CAABB85E29A3F533DD2246 |
Malicious: | false |
Reputation: | low |
URL: | http://4.lkx91.michaelhuegel.com/news |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2877 |
Entropy (8bit): | 4.859680281553471 |
Encrypted: | false |
SSDEEP: | 48:Z5JJpI4LLIk6ddLHJy8A3SXUV/ot5CjsEn+yxw4Dj7jvj:r3LLIk6T9yvGssE5x7 |
MD5: | D789D413AACD394D5DD0F75C7CEDF95A |
SHA1: | CC82AE047F1B66343F8488FE0A017AD1960054DA |
SHA-256: | 59BF80ABE64AEE9944DCBA2930967833C0A96914420E48EF1F94E7136EB171F7 |
SHA-512: | D2BA473C0CC9B83DF0F903CCC8E48C074D7EF8302A45514BF085A542D3C3199E1F217C3B53D9A2405D64D57F19451EAC1CC4F5FE5AFC9DE375BB91DA2B582798 |
Malicious: | false |
Reputation: | low |
URL: | http://4.lkx91.michaelhuegel.com/ |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 714 |
Entropy (8bit): | 4.640934656505668 |
Encrypted: | false |
SSDEEP: | 12:U068a0fvM2SMGRDGW4Q1bTNKqkFk80MFr+jF35PHtXFGSECp3t6FGSECpa6FGSEI:UkvMuGRKePcV1YF3LX8SECVt68SEC06l |
MD5: | 4BE8EF55271B17CF4B27C93F9C21044F |
SHA1: | 9D0DA00EC2C6BD31D3EECCF4F97B9D9DFB409822 |
SHA-256: | 48796E60D0E2924366A3E3BBFC06A948C1D631AB0B8DFA27E2CA9F8EE58053E7 |
SHA-512: | B7ACE1CA1DE39D61154D26C0306AA5EF64E64C08FA1B15EE406CA887D23D59DF30A3FC73E143C8C87B5F71291F9B918DE207DEF1C77AF91046C7564E60CE4517 |
Malicious: | false |
Reputation: | low |
URL: | http://4.lkx91.michaelhuegel.com/assets/about_styles.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1435 |
Entropy (8bit): | 4.7130828204283555 |
Encrypted: | false |
SSDEEP: | 24:UkvMuGRKe7+U6eSEMDSaGvMdufqGmnoSPfzS7pvMugQrYFv0CGSTYFUL9MtDY3Ss:Uk9w7x9sHGgufRNkz09fcFMCGJFUL9MO |
MD5: | 1FB5EDFEA0AF10D301EFCD56738BA30A |
SHA1: | 1AAC6EB08825AD63AC334CFF1F816CC9ECA71219 |
SHA-256: | 161D0961994DD86814FAFBA6EDD6FA7A75D17B19B2E60E1EE01ADAA9EA19DADC |
SHA-512: | A0C3F78B663E01D24DDD53AF6D0D1E3E9DD743C3E4CB6FC8F45588BCC37AB3923A2992505C4842D9E451692A7E7495155F58BFED056BCFE57E02204603F962DD |
Malicious: | false |
Reputation: | low |
URL: | http://4.lkx91.michaelhuegel.com/assets/styles.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2176 |
Entropy (8bit): | 4.633464119861773 |
Encrypted: | false |
SSDEEP: | 48:FrRUUtfTbGHdPJQLwVXjpG6qkdZA98zE9bH2Mjn9TAc:9WUtrbG9bVXsNyA98zEEMjn9TH |
MD5: | ECAA183EFB1A465A09483E3F07A8D9FC |
SHA1: | 2A896975215454ADAEA4AE94F50B8A7E858061C9 |
SHA-256: | C4534B8F7160919D02D7181081898ADB7F03243DC42A257697B42102239B2B3D |
SHA-512: | 054E275BFE8A6204E6E01A15109F4F39EBAAA611F725B9F59ABCD7F5603B4F67CF3E7314F5555EA9E773B6729E8CBF67915D3F875C096442882D46D5DEFDD97B |
Malicious: | false |
Reputation: | low |
URL: | http://4.lkx91.michaelhuegel.com/about |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 16 |
Entropy (8bit): | 3.875 |
Encrypted: | false |
SSDEEP: | 3:HoUinYn:IUyY |
MD5: | 903747EA4323C522742842A52CE710C9 |
SHA1: | 9F806EA4288867A31A4AD53AC171AA4029DF182B |
SHA-256: | 4BD8B60F91849C936AE45615145A7B7BE2CF803322A30BABBAE7267A142CA5BB |
SHA-512: | EEF73DC29A38ED70FFCFC321931BCB5B5A29FAAC356E8F6D84F57C532EEF44AE75021C341CF7DAE26B8211924A1C0E0EC4735F6BFC4AF3970A48EB63BFB7895F |
Malicious: | false |
Reputation: | low |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTMxLjAuNjc3OC4xMDkSGQmC6EcvaJfRhBIFDYOoWz0hgKiKtmPGx8w=?alt=proto |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 31, 2024 17:13:25.448286057 CET | 50589 | 443 | 192.168.2.24 | 150.171.28.10 |
Dec 31, 2024 17:13:25.448287964 CET | 50587 | 443 | 192.168.2.24 | 150.171.28.10 |
Dec 31, 2024 17:13:25.448291063 CET | 50588 | 443 | 192.168.2.24 | 150.171.28.10 |
Dec 31, 2024 17:13:25.448493958 CET | 50590 | 443 | 192.168.2.24 | 150.171.28.10 |
Dec 31, 2024 17:13:25.448494911 CET | 50591 | 80 | 192.168.2.24 | 192.229.221.95 |
Dec 31, 2024 17:13:25.831696033 CET | 80 | 50599 | 204.79.197.203 | 192.168.2.24 |
Dec 31, 2024 17:13:25.831731081 CET | 80 | 50599 | 204.79.197.203 | 192.168.2.24 |
Dec 31, 2024 17:13:25.831933022 CET | 50599 | 80 | 192.168.2.24 | 204.79.197.203 |
Dec 31, 2024 17:13:25.874670982 CET | 50596 | 443 | 192.168.2.24 | 20.189.173.11 |
Dec 31, 2024 17:13:25.874692917 CET | 443 | 50596 | 20.189.173.11 | 192.168.2.24 |
Dec 31, 2024 17:13:25.875950098 CET | 443 | 50596 | 20.189.173.11 | 192.168.2.24 |
Dec 31, 2024 17:13:25.876029968 CET | 50596 | 443 | 192.168.2.24 | 20.189.173.11 |
Dec 31, 2024 17:13:25.878509998 CET | 50596 | 443 | 192.168.2.24 | 20.189.173.11 |
Dec 31, 2024 17:13:25.878583908 CET | 443 | 50596 | 20.189.173.11 | 192.168.2.24 |
Dec 31, 2024 17:13:25.878638029 CET | 50596 | 443 | 192.168.2.24 | 20.189.173.11 |
Dec 31, 2024 17:13:25.878645897 CET | 443 | 50596 | 20.189.173.11 | 192.168.2.24 |
Dec 31, 2024 17:13:25.878688097 CET | 50596 | 443 | 192.168.2.24 | 20.189.173.11 |
Dec 31, 2024 17:13:25.878907919 CET | 50596 | 443 | 192.168.2.24 | 20.189.173.11 |
Dec 31, 2024 17:13:25.879036903 CET | 50596 | 443 | 192.168.2.24 | 20.189.173.11 |
Dec 31, 2024 17:13:25.879070997 CET | 443 | 50596 | 20.189.173.11 | 192.168.2.24 |
Dec 31, 2024 17:13:25.879446983 CET | 50596 | 443 | 192.168.2.24 | 20.189.173.11 |
Dec 31, 2024 17:13:25.879483938 CET | 443 | 50596 | 20.189.173.11 | 192.168.2.24 |
Dec 31, 2024 17:13:25.879539013 CET | 50596 | 443 | 192.168.2.24 | 20.189.173.11 |
Dec 31, 2024 17:13:36.028824091 CET | 50608 | 443 | 192.168.2.24 | 142.250.184.228 |
Dec 31, 2024 17:13:36.028879881 CET | 443 | 50608 | 142.250.184.228 | 192.168.2.24 |
Dec 31, 2024 17:13:36.028958082 CET | 50608 | 443 | 192.168.2.24 | 142.250.184.228 |
Dec 31, 2024 17:13:36.029203892 CET | 50608 | 443 | 192.168.2.24 | 142.250.184.228 |
Dec 31, 2024 17:13:36.029222012 CET | 443 | 50608 | 142.250.184.228 | 192.168.2.24 |
Dec 31, 2024 17:13:36.876760960 CET | 443 | 50608 | 142.250.184.228 | 192.168.2.24 |
Dec 31, 2024 17:13:36.877409935 CET | 50608 | 443 | 192.168.2.24 | 142.250.184.228 |
Dec 31, 2024 17:13:36.877441883 CET | 443 | 50608 | 142.250.184.228 | 192.168.2.24 |
Dec 31, 2024 17:13:36.880553007 CET | 443 | 50608 | 142.250.184.228 | 192.168.2.24 |
Dec 31, 2024 17:13:36.880611897 CET | 50608 | 443 | 192.168.2.24 | 142.250.184.228 |
Dec 31, 2024 17:13:36.882091045 CET | 50608 | 443 | 192.168.2.24 | 142.250.184.228 |
Dec 31, 2024 17:13:36.882172108 CET | 443 | 50608 | 142.250.184.228 | 192.168.2.24 |
Dec 31, 2024 17:13:36.928888083 CET | 50608 | 443 | 192.168.2.24 | 142.250.184.228 |
Dec 31, 2024 17:13:36.928910017 CET | 443 | 50608 | 142.250.184.228 | 192.168.2.24 |
Dec 31, 2024 17:13:36.975877047 CET | 50608 | 443 | 192.168.2.24 | 142.250.184.228 |
Dec 31, 2024 17:13:37.003264904 CET | 443 | 50567 | 23.56.210.49 | 192.168.2.24 |
Dec 31, 2024 17:13:37.003448963 CET | 443 | 50567 | 23.56.210.49 | 192.168.2.24 |
Dec 31, 2024 17:13:37.003719091 CET | 50567 | 443 | 192.168.2.24 | 23.56.210.49 |
Dec 31, 2024 17:13:37.004132032 CET | 443 | 50566 | 23.56.210.49 | 192.168.2.24 |
Dec 31, 2024 17:13:37.004211903 CET | 443 | 50566 | 23.56.210.49 | 192.168.2.24 |
Dec 31, 2024 17:13:37.004281998 CET | 50566 | 443 | 192.168.2.24 | 23.56.210.49 |
Dec 31, 2024 17:13:37.055320978 CET | 443 | 50565 | 23.56.210.49 | 192.168.2.24 |
Dec 31, 2024 17:13:37.055392027 CET | 443 | 50565 | 23.56.210.49 | 192.168.2.24 |
Dec 31, 2024 17:13:37.055464029 CET | 50565 | 443 | 192.168.2.24 | 23.56.210.49 |
Dec 31, 2024 17:13:37.375031948 CET | 50610 | 443 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:37.375102043 CET | 443 | 50610 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:37.375195980 CET | 50610 | 443 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:37.375416040 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:37.375610113 CET | 50612 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:37.376108885 CET | 50610 | 443 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:37.376127005 CET | 443 | 50610 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:37.380264044 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:37.380338907 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:37.380383968 CET | 80 | 50612 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:37.380429029 CET | 50612 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:38.817296028 CET | 443 | 50610 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:38.817397118 CET | 443 | 50610 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:38.817468882 CET | 50610 | 443 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:38.817687035 CET | 50610 | 443 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:38.817708969 CET | 443 | 50610 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:38.818417072 CET | 50614 | 443 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:38.818461895 CET | 443 | 50614 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:38.818563938 CET | 50614 | 443 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:38.819401026 CET | 50614 | 443 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:38.819417000 CET | 443 | 50614 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:40.261193037 CET | 443 | 50614 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:40.261545897 CET | 443 | 50614 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:40.261796951 CET | 50614 | 443 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:40.261885881 CET | 50614 | 443 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:40.261909008 CET | 443 | 50614 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:40.264964104 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:40.269763947 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:40.445447922 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:40.445466995 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:40.445481062 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:40.445697069 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:40.544725895 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:40.549596071 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:40.725084066 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:40.776979923 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:46.802436113 CET | 443 | 50608 | 142.250.184.228 | 192.168.2.24 |
Dec 31, 2024 17:13:46.802522898 CET | 443 | 50608 | 142.250.184.228 | 192.168.2.24 |
Dec 31, 2024 17:13:46.802841902 CET | 50608 | 443 | 192.168.2.24 | 142.250.184.228 |
Dec 31, 2024 17:13:48.729816914 CET | 50608 | 443 | 192.168.2.24 | 142.250.184.228 |
Dec 31, 2024 17:13:48.729849100 CET | 443 | 50608 | 142.250.184.228 | 192.168.2.24 |
Dec 31, 2024 17:13:51.379560947 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:51.384509087 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:51.577927113 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:51.577939034 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:51.577949047 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:51.577960014 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:51.578037024 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:51.578073025 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:51.616755962 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:51.621659040 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:51.797399998 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:51.797416925 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:13:51.797486067 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:13:56.911048889 CET | 50623 | 443 | 192.168.2.24 | 152.199.21.175 |
Dec 31, 2024 17:13:56.911150932 CET | 443 | 50623 | 152.199.21.175 | 192.168.2.24 |
Dec 31, 2024 17:13:56.911252975 CET | 50623 | 443 | 192.168.2.24 | 152.199.21.175 |
Dec 31, 2024 17:13:56.978523970 CET | 50623 | 443 | 192.168.2.24 | 152.199.21.175 |
Dec 31, 2024 17:13:56.978562117 CET | 443 | 50623 | 152.199.21.175 | 192.168.2.24 |
Dec 31, 2024 17:13:57.791747093 CET | 443 | 50623 | 152.199.21.175 | 192.168.2.24 |
Dec 31, 2024 17:13:57.792785883 CET | 50623 | 443 | 192.168.2.24 | 152.199.21.175 |
Dec 31, 2024 17:13:57.948190928 CET | 50623 | 443 | 192.168.2.24 | 152.199.21.175 |
Dec 31, 2024 17:13:57.948218107 CET | 443 | 50623 | 152.199.21.175 | 192.168.2.24 |
Dec 31, 2024 17:13:57.949502945 CET | 443 | 50623 | 152.199.21.175 | 192.168.2.24 |
Dec 31, 2024 17:13:57.949572086 CET | 50623 | 443 | 192.168.2.24 | 152.199.21.175 |
Dec 31, 2024 17:13:57.952879906 CET | 50623 | 443 | 192.168.2.24 | 152.199.21.175 |
Dec 31, 2024 17:13:57.953046083 CET | 443 | 50623 | 152.199.21.175 | 192.168.2.24 |
Dec 31, 2024 17:13:57.953097105 CET | 50623 | 443 | 192.168.2.24 | 152.199.21.175 |
Dec 31, 2024 17:13:57.953113079 CET | 443 | 50623 | 152.199.21.175 | 192.168.2.24 |
Dec 31, 2024 17:13:57.953150988 CET | 50623 | 443 | 192.168.2.24 | 152.199.21.175 |
Dec 31, 2024 17:13:58.007247925 CET | 50623 | 443 | 192.168.2.24 | 152.199.21.175 |
Dec 31, 2024 17:13:58.051342010 CET | 443 | 50623 | 152.199.21.175 | 192.168.2.24 |
Dec 31, 2024 17:13:58.189960957 CET | 443 | 50623 | 152.199.21.175 | 192.168.2.24 |
Dec 31, 2024 17:13:58.190017939 CET | 443 | 50623 | 152.199.21.175 | 192.168.2.24 |
Dec 31, 2024 17:13:58.190083027 CET | 50623 | 443 | 192.168.2.24 | 152.199.21.175 |
Dec 31, 2024 17:13:58.190099955 CET | 443 | 50623 | 152.199.21.175 | 192.168.2.24 |
Dec 31, 2024 17:13:58.190166950 CET | 50623 | 443 | 192.168.2.24 | 152.199.21.175 |
Dec 31, 2024 17:13:58.194246054 CET | 50623 | 443 | 192.168.2.24 | 152.199.21.175 |
Dec 31, 2024 17:13:58.194271088 CET | 443 | 50623 | 152.199.21.175 | 192.168.2.24 |
Dec 31, 2024 17:13:58.194283009 CET | 50623 | 443 | 192.168.2.24 | 152.199.21.175 |
Dec 31, 2024 17:13:58.194334030 CET | 50623 | 443 | 192.168.2.24 | 152.199.21.175 |
Dec 31, 2024 17:14:02.420013905 CET | 50555 | 443 | 192.168.2.24 | 204.79.197.203 |
Dec 31, 2024 17:14:02.424823999 CET | 443 | 50555 | 204.79.197.203 | 192.168.2.24 |
Dec 31, 2024 17:14:03.219012976 CET | 50572 | 443 | 192.168.2.24 | 20.110.205.119 |
Dec 31, 2024 17:14:03.219053984 CET | 50571 | 443 | 192.168.2.24 | 204.79.197.237 |
Dec 31, 2024 17:14:03.223951101 CET | 443 | 50572 | 20.110.205.119 | 192.168.2.24 |
Dec 31, 2024 17:14:03.223977089 CET | 443 | 50571 | 204.79.197.237 | 192.168.2.24 |
Dec 31, 2024 17:14:03.331026077 CET | 50569 | 443 | 192.168.2.24 | 18.238.49.124 |
Dec 31, 2024 17:14:03.335979939 CET | 443 | 50569 | 18.238.49.124 | 192.168.2.24 |
Dec 31, 2024 17:14:03.362020016 CET | 50570 | 443 | 192.168.2.24 | 204.79.197.203 |
Dec 31, 2024 17:14:03.366859913 CET | 443 | 50570 | 204.79.197.203 | 192.168.2.24 |
Dec 31, 2024 17:14:03.438534975 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:14:03.443490028 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:03.619194984 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:03.619219065 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:03.619234085 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:03.619277000 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:14:03.647871971 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:14:03.652746916 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:03.839912891 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:03.886992931 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:14:05.887023926 CET | 50583 | 443 | 192.168.2.24 | 23.44.203.173 |
Dec 31, 2024 17:14:05.892004967 CET | 443 | 50583 | 23.44.203.173 | 192.168.2.24 |
Dec 31, 2024 17:14:06.030997038 CET | 50584 | 443 | 192.168.2.24 | 204.79.197.203 |
Dec 31, 2024 17:14:06.035839081 CET | 443 | 50584 | 204.79.197.203 | 192.168.2.24 |
Dec 31, 2024 17:14:06.680417061 CET | 50564 | 443 | 192.168.2.24 | 23.51.56.166 |
Dec 31, 2024 17:14:06.685257912 CET | 443 | 50564 | 23.51.56.166 | 192.168.2.24 |
Dec 31, 2024 17:14:07.052045107 CET | 50557 | 443 | 192.168.2.24 | 72.21.81.200 |
Dec 31, 2024 17:14:07.056977034 CET | 443 | 50557 | 72.21.81.200 | 192.168.2.24 |
Dec 31, 2024 17:14:07.355011940 CET | 50553 | 443 | 192.168.2.24 | 104.117.182.59 |
Dec 31, 2024 17:14:07.359925985 CET | 443 | 50553 | 104.117.182.59 | 192.168.2.24 |
Dec 31, 2024 17:14:07.979090929 CET | 50568 | 443 | 192.168.2.24 | 51.104.15.252 |
Dec 31, 2024 17:14:07.984034061 CET | 443 | 50568 | 51.104.15.252 | 192.168.2.24 |
Dec 31, 2024 17:14:14.369229078 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:14:14.374224901 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:14.549768925 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:14.549794912 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:14.549844980 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:14:14.549850941 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:14.549865007 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:14.549982071 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:14:16.255161047 CET | 49729 | 80 | 192.168.2.24 | 192.229.221.95 |
Dec 31, 2024 17:14:16.255209923 CET | 49727 | 443 | 192.168.2.24 | 51.137.3.145 |
Dec 31, 2024 17:14:16.255256891 CET | 49732 | 80 | 192.168.2.24 | 204.79.197.203 |
Dec 31, 2024 17:14:16.260271072 CET | 80 | 49729 | 192.229.221.95 | 192.168.2.24 |
Dec 31, 2024 17:14:16.260409117 CET | 49729 | 80 | 192.168.2.24 | 192.229.221.95 |
Dec 31, 2024 17:14:16.260818958 CET | 443 | 49727 | 51.137.3.145 | 192.168.2.24 |
Dec 31, 2024 17:14:16.260832071 CET | 80 | 49732 | 204.79.197.203 | 192.168.2.24 |
Dec 31, 2024 17:14:16.260871887 CET | 49727 | 443 | 192.168.2.24 | 51.137.3.145 |
Dec 31, 2024 17:14:16.260895967 CET | 49732 | 80 | 192.168.2.24 | 204.79.197.203 |
Dec 31, 2024 17:14:16.497615099 CET | 50625 | 80 | 192.168.2.24 | 172.217.16.131 |
Dec 31, 2024 17:14:16.503668070 CET | 80 | 50625 | 172.217.16.131 | 192.168.2.24 |
Dec 31, 2024 17:14:16.503741980 CET | 50625 | 80 | 192.168.2.24 | 172.217.16.131 |
Dec 31, 2024 17:14:16.503844023 CET | 50625 | 80 | 192.168.2.24 | 172.217.16.131 |
Dec 31, 2024 17:14:16.510015965 CET | 80 | 50625 | 172.217.16.131 | 192.168.2.24 |
Dec 31, 2024 17:14:17.114521027 CET | 80 | 50625 | 172.217.16.131 | 192.168.2.24 |
Dec 31, 2024 17:14:17.130256891 CET | 50626 | 80 | 192.168.2.24 | 2.23.197.184 |
Dec 31, 2024 17:14:17.135209084 CET | 80 | 50626 | 2.23.197.184 | 192.168.2.24 |
Dec 31, 2024 17:14:17.135359049 CET | 50626 | 80 | 192.168.2.24 | 2.23.197.184 |
Dec 31, 2024 17:14:17.135473013 CET | 50626 | 80 | 192.168.2.24 | 2.23.197.184 |
Dec 31, 2024 17:14:17.140396118 CET | 80 | 50626 | 2.23.197.184 | 192.168.2.24 |
Dec 31, 2024 17:14:17.166057110 CET | 50625 | 80 | 192.168.2.24 | 172.217.16.131 |
Dec 31, 2024 17:14:17.774312019 CET | 80 | 50626 | 2.23.197.184 | 192.168.2.24 |
Dec 31, 2024 17:14:17.782656908 CET | 50552 | 80 | 192.168.2.24 | 199.232.210.172 |
Dec 31, 2024 17:14:17.782757998 CET | 50563 | 80 | 192.168.2.24 | 199.232.210.172 |
Dec 31, 2024 17:14:17.787702084 CET | 80 | 50552 | 199.232.210.172 | 192.168.2.24 |
Dec 31, 2024 17:14:17.787785053 CET | 50552 | 80 | 192.168.2.24 | 199.232.210.172 |
Dec 31, 2024 17:14:17.788003922 CET | 80 | 50563 | 199.232.210.172 | 192.168.2.24 |
Dec 31, 2024 17:14:17.788065910 CET | 50563 | 80 | 192.168.2.24 | 199.232.210.172 |
Dec 31, 2024 17:14:17.822067976 CET | 50626 | 80 | 192.168.2.24 | 2.23.197.184 |
Dec 31, 2024 17:14:22.018058062 CET | 50567 | 443 | 192.168.2.24 | 23.56.210.49 |
Dec 31, 2024 17:14:22.018096924 CET | 50566 | 443 | 192.168.2.24 | 23.56.210.49 |
Dec 31, 2024 17:14:22.023004055 CET | 443 | 50567 | 23.56.210.49 | 192.168.2.24 |
Dec 31, 2024 17:14:22.023025990 CET | 443 | 50566 | 23.56.210.49 | 192.168.2.24 |
Dec 31, 2024 17:14:22.064054966 CET | 50565 | 443 | 192.168.2.24 | 23.56.210.49 |
Dec 31, 2024 17:14:22.068855047 CET | 443 | 50565 | 23.56.210.49 | 192.168.2.24 |
Dec 31, 2024 17:14:22.383096933 CET | 50612 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:14:22.388129950 CET | 80 | 50612 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:25.235430002 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:14:25.240416050 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:25.417233944 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:25.417349100 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:25.417362928 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:25.417432070 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:14:33.502326965 CET | 80 | 50599 | 204.79.197.203 | 192.168.2.24 |
Dec 31, 2024 17:14:33.502401114 CET | 50599 | 80 | 192.168.2.24 | 204.79.197.203 |
Dec 31, 2024 17:14:33.502500057 CET | 50599 | 80 | 192.168.2.24 | 204.79.197.203 |
Dec 31, 2024 17:14:33.507232904 CET | 80 | 50599 | 204.79.197.203 | 192.168.2.24 |
Dec 31, 2024 17:14:36.076564074 CET | 50632 | 443 | 192.168.2.24 | 142.250.184.228 |
Dec 31, 2024 17:14:36.076658010 CET | 443 | 50632 | 142.250.184.228 | 192.168.2.24 |
Dec 31, 2024 17:14:36.076759100 CET | 50632 | 443 | 192.168.2.24 | 142.250.184.228 |
Dec 31, 2024 17:14:36.077217102 CET | 50632 | 443 | 192.168.2.24 | 142.250.184.228 |
Dec 31, 2024 17:14:36.077255011 CET | 443 | 50632 | 142.250.184.228 | 192.168.2.24 |
Dec 31, 2024 17:14:36.908265114 CET | 443 | 50632 | 142.250.184.228 | 192.168.2.24 |
Dec 31, 2024 17:14:36.908826113 CET | 50632 | 443 | 192.168.2.24 | 142.250.184.228 |
Dec 31, 2024 17:14:36.908900976 CET | 443 | 50632 | 142.250.184.228 | 192.168.2.24 |
Dec 31, 2024 17:14:36.909256935 CET | 443 | 50632 | 142.250.184.228 | 192.168.2.24 |
Dec 31, 2024 17:14:36.912811995 CET | 50632 | 443 | 192.168.2.24 | 142.250.184.228 |
Dec 31, 2024 17:14:36.912892103 CET | 443 | 50632 | 142.250.184.228 | 192.168.2.24 |
Dec 31, 2024 17:14:36.970207930 CET | 50632 | 443 | 192.168.2.24 | 142.250.184.228 |
Dec 31, 2024 17:14:37.108808994 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:14:37.113713026 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:37.289410114 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:37.289424896 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:37.289450884 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:37.289463043 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:37.289478064 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:14:37.289527893 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:14:37.870255947 CET | 50612 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:14:37.875371933 CET | 80 | 50612 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:37.875433922 CET | 50612 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:14:42.219218969 CET | 49673 | 443 | 192.168.2.24 | 20.198.118.190 |
Dec 31, 2024 17:14:42.219280958 CET | 443 | 49673 | 20.198.118.190 | 192.168.2.24 |
Dec 31, 2024 17:14:42.843816042 CET | 50633 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:42.843863010 CET | 443 | 50633 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:42.844088078 CET | 50633 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:42.844974041 CET | 50633 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:42.844984055 CET | 443 | 50633 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:43.668091059 CET | 443 | 50633 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:43.668292999 CET | 50633 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:43.680257082 CET | 50633 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:43.680279970 CET | 443 | 50633 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:43.680732012 CET | 443 | 50633 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:43.733170033 CET | 50633 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:44.844340086 CET | 50633 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:44.844419003 CET | 50633 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:44.844429016 CET | 443 | 50633 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:44.844552994 CET | 50633 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:44.891325951 CET | 443 | 50633 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:45.023050070 CET | 443 | 50633 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:45.023184061 CET | 443 | 50633 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:45.023236990 CET | 50633 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:45.023360968 CET | 50633 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:45.023375034 CET | 443 | 50633 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:45.656543970 CET | 50635 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:45.656635046 CET | 443 | 50635 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:45.656735897 CET | 50635 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:45.657556057 CET | 50635 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:45.657579899 CET | 443 | 50635 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:46.448414087 CET | 443 | 50635 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:46.448499918 CET | 50635 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:46.450850964 CET | 50635 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:46.450870991 CET | 443 | 50635 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:46.451654911 CET | 443 | 50635 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:46.455777884 CET | 50635 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:46.455904007 CET | 50635 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:46.455920935 CET | 443 | 50635 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:46.455966949 CET | 50635 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:46.499336004 CET | 443 | 50635 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:46.631299019 CET | 443 | 50635 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:46.631572962 CET | 443 | 50635 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:46.633486032 CET | 50635 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:46.634869099 CET | 50635 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:46.634900093 CET | 443 | 50635 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:46.850650072 CET | 443 | 50632 | 142.250.184.228 | 192.168.2.24 |
Dec 31, 2024 17:14:46.850738049 CET | 443 | 50632 | 142.250.184.228 | 192.168.2.24 |
Dec 31, 2024 17:14:46.850905895 CET | 50632 | 443 | 192.168.2.24 | 142.250.184.228 |
Dec 31, 2024 17:14:47.357325077 CET | 50632 | 443 | 192.168.2.24 | 142.250.184.228 |
Dec 31, 2024 17:14:47.357413054 CET | 443 | 50632 | 142.250.184.228 | 192.168.2.24 |
Dec 31, 2024 17:14:47.436156988 CET | 50555 | 443 | 192.168.2.24 | 204.79.197.203 |
Dec 31, 2024 17:14:47.441118956 CET | 443 | 50555 | 204.79.197.203 | 192.168.2.24 |
Dec 31, 2024 17:14:48.234181881 CET | 50572 | 443 | 192.168.2.24 | 20.110.205.119 |
Dec 31, 2024 17:14:48.234323978 CET | 50571 | 443 | 192.168.2.24 | 204.79.197.237 |
Dec 31, 2024 17:14:48.239094019 CET | 443 | 50572 | 20.110.205.119 | 192.168.2.24 |
Dec 31, 2024 17:14:48.239109039 CET | 443 | 50571 | 204.79.197.237 | 192.168.2.24 |
Dec 31, 2024 17:14:48.347943068 CET | 50569 | 443 | 192.168.2.24 | 18.238.49.124 |
Dec 31, 2024 17:14:48.352751017 CET | 443 | 50569 | 18.238.49.124 | 192.168.2.24 |
Dec 31, 2024 17:14:48.380851030 CET | 50570 | 443 | 192.168.2.24 | 204.79.197.203 |
Dec 31, 2024 17:14:48.386746883 CET | 443 | 50570 | 204.79.197.203 | 192.168.2.24 |
Dec 31, 2024 17:14:49.168839931 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:14:49.172363997 CET | 50636 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:14:49.173783064 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:49.177145958 CET | 80 | 50636 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:49.177216053 CET | 50636 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:14:49.349778891 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:49.349795103 CET | 80 | 50611 | 185.246.85.141 | 192.168.2.24 |
Dec 31, 2024 17:14:49.349858999 CET | 50611 | 80 | 192.168.2.24 | 185.246.85.141 |
Dec 31, 2024 17:14:50.208775997 CET | 443 | 49726 | 2.16.158.192 | 192.168.2.24 |
Dec 31, 2024 17:14:50.208908081 CET | 443 | 49726 | 2.16.158.192 | 192.168.2.24 |
Dec 31, 2024 17:14:50.208949089 CET | 49726 | 443 | 192.168.2.24 | 2.16.158.192 |
Dec 31, 2024 17:14:50.208997011 CET | 49726 | 443 | 192.168.2.24 | 2.16.158.192 |
Dec 31, 2024 17:14:50.892265081 CET | 50583 | 443 | 192.168.2.24 | 23.44.203.173 |
Dec 31, 2024 17:14:50.897131920 CET | 443 | 50583 | 23.44.203.173 | 192.168.2.24 |
Dec 31, 2024 17:14:51.050235987 CET | 50584 | 443 | 192.168.2.24 | 204.79.197.203 |
Dec 31, 2024 17:14:51.055056095 CET | 443 | 50584 | 204.79.197.203 | 192.168.2.24 |
Dec 31, 2024 17:14:51.689218044 CET | 50564 | 443 | 192.168.2.24 | 23.51.56.166 |
Dec 31, 2024 17:14:51.694174051 CET | 443 | 50564 | 23.51.56.166 | 192.168.2.24 |
Dec 31, 2024 17:14:52.057209015 CET | 50557 | 443 | 192.168.2.24 | 72.21.81.200 |
Dec 31, 2024 17:14:52.062064886 CET | 443 | 50557 | 72.21.81.200 | 192.168.2.24 |
Dec 31, 2024 17:14:52.363862991 CET | 50553 | 443 | 192.168.2.24 | 104.117.182.59 |
Dec 31, 2024 17:14:52.368714094 CET | 443 | 50553 | 104.117.182.59 | 192.168.2.24 |
Dec 31, 2024 17:14:52.984277010 CET | 50568 | 443 | 192.168.2.24 | 51.104.15.252 |
Dec 31, 2024 17:14:52.989240885 CET | 443 | 50568 | 51.104.15.252 | 192.168.2.24 |
Dec 31, 2024 17:14:54.516586065 CET | 49728 | 443 | 192.168.2.24 | 104.126.37.201 |
Dec 31, 2024 17:14:54.522068977 CET | 443 | 49728 | 104.126.37.201 | 192.168.2.24 |
Dec 31, 2024 17:14:54.522211075 CET | 49728 | 443 | 192.168.2.24 | 104.126.37.201 |
Dec 31, 2024 17:14:54.736224890 CET | 50637 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:54.736268044 CET | 443 | 50637 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:54.736349106 CET | 50637 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:54.737267971 CET | 50637 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:54.737281084 CET | 443 | 50637 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:55.549637079 CET | 443 | 50637 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:55.549731016 CET | 50637 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:55.554913044 CET | 50637 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:55.554924965 CET | 443 | 50637 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:55.555171013 CET | 443 | 50637 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:55.558279991 CET | 50637 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:55.558279991 CET | 50637 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:55.558296919 CET | 443 | 50637 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:55.558511019 CET | 50637 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:55.599343061 CET | 443 | 50637 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:55.738835096 CET | 443 | 50637 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:55.738914013 CET | 443 | 50637 | 40.115.3.253 | 192.168.2.24 |
Dec 31, 2024 17:14:55.739021063 CET | 50637 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:55.739310980 CET | 50637 | 443 | 192.168.2.24 | 40.115.3.253 |
Dec 31, 2024 17:14:55.739331007 CET | 443 | 50637 | 40.115.3.253 | 192.168.2.24 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 31, 2024 17:13:31.876594067 CET | 53 | 57958 | 1.1.1.1 | 192.168.2.24 |
Dec 31, 2024 17:13:33.066226006 CET | 53 | 54308 | 1.1.1.1 | 192.168.2.24 |
Dec 31, 2024 17:13:36.021064043 CET | 59319 | 53 | 192.168.2.24 | 1.1.1.1 |
Dec 31, 2024 17:13:36.021111965 CET | 58321 | 53 | 192.168.2.24 | 1.1.1.1 |
Dec 31, 2024 17:13:36.028079033 CET | 53 | 58321 | 1.1.1.1 | 192.168.2.24 |
Dec 31, 2024 17:13:36.028091908 CET | 53 | 59319 | 1.1.1.1 | 192.168.2.24 |
Dec 31, 2024 17:13:37.337737083 CET | 59124 | 53 | 192.168.2.24 | 1.1.1.1 |
Dec 31, 2024 17:13:37.338078976 CET | 55798 | 53 | 192.168.2.24 | 1.1.1.1 |
Dec 31, 2024 17:13:37.351218939 CET | 53 | 55798 | 1.1.1.1 | 192.168.2.24 |
Dec 31, 2024 17:13:37.355732918 CET | 65519 | 53 | 192.168.2.24 | 1.1.1.1 |
Dec 31, 2024 17:13:37.355958939 CET | 54909 | 53 | 192.168.2.24 | 1.1.1.1 |
Dec 31, 2024 17:13:37.367873907 CET | 53 | 65519 | 1.1.1.1 | 192.168.2.24 |
Dec 31, 2024 17:13:37.374178886 CET | 53 | 59124 | 1.1.1.1 | 192.168.2.24 |
Dec 31, 2024 17:13:37.389637947 CET | 53 | 54909 | 1.1.1.1 | 192.168.2.24 |
Dec 31, 2024 17:13:40.483577013 CET | 54037 | 53 | 192.168.2.24 | 1.1.1.1 |
Dec 31, 2024 17:13:40.483735085 CET | 53204 | 53 | 192.168.2.24 | 1.1.1.1 |
Dec 31, 2024 17:13:40.491553068 CET | 53 | 53204 | 1.1.1.1 | 192.168.2.24 |
Dec 31, 2024 17:13:50.014015913 CET | 53 | 63561 | 1.1.1.1 | 192.168.2.24 |
Dec 31, 2024 17:13:51.830204964 CET | 53 | 57362 | 1.1.1.1 | 192.168.2.24 |
Dec 31, 2024 17:14:00.977829933 CET | 53 | 50862 | 1.1.1.1 | 192.168.2.24 |
Dec 31, 2024 17:14:08.831748962 CET | 53 | 61052 | 1.1.1.1 | 192.168.2.24 |
Dec 31, 2024 17:14:31.294648886 CET | 53 | 55076 | 1.1.1.1 | 192.168.2.24 |
Dec 31, 2024 17:14:31.738518953 CET | 53 | 52337 | 1.1.1.1 | 192.168.2.24 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Dec 31, 2024 17:13:37.389727116 CET | 192.168.2.24 | 1.1.1.1 | c23f | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 31, 2024 17:13:36.021064043 CET | 192.168.2.24 | 1.1.1.1 | 0x534d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 31, 2024 17:13:36.021111965 CET | 192.168.2.24 | 1.1.1.1 | 0x4fba | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 31, 2024 17:13:37.337737083 CET | 192.168.2.24 | 1.1.1.1 | 0xb90a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 31, 2024 17:13:37.338078976 CET | 192.168.2.24 | 1.1.1.1 | 0xc8fe | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 31, 2024 17:13:37.355732918 CET | 192.168.2.24 | 1.1.1.1 | 0x3273 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 31, 2024 17:13:37.355958939 CET | 192.168.2.24 | 1.1.1.1 | 0x12e0 | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 31, 2024 17:13:40.483577013 CET | 192.168.2.24 | 1.1.1.1 | 0xe099 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 31, 2024 17:13:40.483735085 CET | 192.168.2.24 | 1.1.1.1 | 0xfde2 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 31, 2024 17:13:36.028079033 CET | 1.1.1.1 | 192.168.2.24 | 0x4fba | No error (0) | 65 | IN (0x0001) | false | |||
Dec 31, 2024 17:13:36.028091908 CET | 1.1.1.1 | 192.168.2.24 | 0x534d | No error (0) | 142.250.184.228 | A (IP address) | IN (0x0001) | false | ||
Dec 31, 2024 17:13:37.367873907 CET | 1.1.1.1 | 192.168.2.24 | 0x3273 | No error (0) | 185.246.85.141 | A (IP address) | IN (0x0001) | false | ||
Dec 31, 2024 17:13:37.374178886 CET | 1.1.1.1 | 192.168.2.24 | 0xb90a | No error (0) | 185.246.85.141 | A (IP address) | IN (0x0001) | false | ||
Dec 31, 2024 17:13:40.491553068 CET | 1.1.1.1 | 192.168.2.24 | 0xfde2 | No error (0) | j.sni.global.fastly.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:13:40.493356943 CET | 1.1.1.1 | 192.168.2.24 | 0xe099 | No error (0) | j.sni.global.fastly.net | CNAME (Canonical name) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.24 | 50599 | 204.79.197.203 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 31, 2024 17:13:25.831696033 CET | 1236 | IN | |
Dec 31, 2024 17:13:25.831731081 CET | 1227 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.24 | 50611 | 185.246.85.141 | 80 | 1208 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 31, 2024 17:13:40.264964104 CET | 510 | OUT | |
Dec 31, 2024 17:13:40.445447922 CET | 1236 | IN | |
Dec 31, 2024 17:13:40.445466995 CET | 1236 | IN | |
Dec 31, 2024 17:13:40.445481062 CET | 1001 | IN | |
Dec 31, 2024 17:13:40.544725895 CET | 464 | OUT | |
Dec 31, 2024 17:13:40.725084066 CET | 258 | IN | |
Dec 31, 2024 17:13:51.379560947 CET | 554 | OUT | |
Dec 31, 2024 17:13:51.577927113 CET | 1236 | IN | |
Dec 31, 2024 17:13:51.577939034 CET | 224 | IN | |
Dec 31, 2024 17:13:51.577949047 CET | 1236 | IN | |
Dec 31, 2024 17:13:51.577960014 CET | 459 | IN | |
Dec 31, 2024 17:13:51.616755962 CET | 354 | OUT | |
Dec 31, 2024 17:13:51.797399998 CET | 1236 | IN | |
Dec 31, 2024 17:13:51.797416925 CET | 384 | IN | |
Dec 31, 2024 17:14:03.438534975 CET | 489 | OUT | |
Dec 31, 2024 17:14:03.619194984 CET | 1236 | IN | |
Dec 31, 2024 17:14:03.619219065 CET | 224 | IN | |
Dec 31, 2024 17:14:03.619234085 CET | 993 | IN | |
Dec 31, 2024 17:14:03.647871971 CET | 365 | OUT | |
Dec 31, 2024 17:14:03.839912891 CET | 898 | IN | |
Dec 31, 2024 17:14:14.369229078 CET | 489 | OUT | |
Dec 31, 2024 17:14:14.549768925 CET | 1236 | IN | |
Dec 31, 2024 17:14:14.549794912 CET | 224 | IN | |
Dec 31, 2024 17:14:14.549850941 CET | 1236 | IN | |
Dec 31, 2024 17:14:25.235430002 CET | 488 | OUT | |
Dec 31, 2024 17:14:25.417233944 CET | 1236 | IN | |
Dec 31, 2024 17:14:37.108808994 CET | 488 | OUT | |
Dec 31, 2024 17:14:37.289410114 CET | 1236 | IN | |
Dec 31, 2024 17:14:49.168839931 CET | 489 | OUT | |
Dec 31, 2024 17:14:49.349778891 CET | 1236 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
2 | 192.168.2.24 | 50625 | 172.217.16.131 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 31, 2024 17:14:16.503844023 CET | 200 | OUT | |
Dec 31, 2024 17:14:17.114521027 CET | 223 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
3 | 192.168.2.24 | 50626 | 2.23.197.184 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 31, 2024 17:14:17.135473013 CET | 227 | OUT | |
Dec 31, 2024 17:14:17.774312019 CET | 1023 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.24 | 50612 | 185.246.85.141 | 80 | 1208 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 31, 2024 17:14:22.383096933 CET | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.24 | 50592 | 23.201.169.47 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-31 16:13:22 UTC | 746 | OUT | |
2024-12-31 16:13:22 UTC | 203 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
1 | 192.168.2.24 | 50596 | 20.189.173.11 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-31 16:13:25 UTC | 473 | OUT | |
2024-12-31 16:13:25 UTC | 4605 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.24 | 50623 | 152.199.21.175 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-31 16:13:58 UTC | 399 | OUT | |
2024-12-31 16:13:58 UTC | 1143 | IN | |
2024-12-31 16:13:58 UTC | 2495 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
3 | 192.168.2.24 | 50633 | 40.115.3.253 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-31 16:14:44 UTC | 71 | OUT | |
2024-12-31 16:14:44 UTC | 260 | OUT | |
2024-12-31 16:14:44 UTC | 1084 | OUT | |
2024-12-31 16:14:44 UTC | 224 | OUT | |
2024-12-31 16:14:45 UTC | 14 | IN | |
2024-12-31 16:14:45 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
4 | 192.168.2.24 | 50635 | 40.115.3.253 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-31 16:14:46 UTC | 71 | OUT | |
2024-12-31 16:14:46 UTC | 260 | OUT | |
2024-12-31 16:14:46 UTC | 1084 | OUT | |
2024-12-31 16:14:46 UTC | 224 | OUT | |
2024-12-31 16:14:46 UTC | 14 | IN | |
2024-12-31 16:14:46 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
5 | 192.168.2.24 | 50637 | 40.115.3.253 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-31 16:14:55 UTC | 71 | OUT | |
2024-12-31 16:14:55 UTC | 260 | OUT | |
2024-12-31 16:14:55 UTC | 1084 | OUT | |
2024-12-31 16:14:55 UTC | 224 | OUT | |
2024-12-31 16:14:55 UTC | 14 | IN | |
2024-12-31 16:14:55 UTC | 58 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 11:13:29 |
Start date: | 31/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6fc7d0000 |
File size: | 3'001'952 bytes |
MD5 hash: | 290DF23002E9B52249B5549F0C668A86 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 11:13:30 |
Start date: | 31/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6fc7d0000 |
File size: | 3'001'952 bytes |
MD5 hash: | 290DF23002E9B52249B5549F0C668A86 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 7 |
Start time: | 11:13:36 |
Start date: | 31/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6fc7d0000 |
File size: | 3'001'952 bytes |
MD5 hash: | 290DF23002E9B52249B5549F0C668A86 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |